More on Threat Hunting
Earlier this week hellor00t asked via Twitter : Where would you place your security researchers/hunt team? I replied : For me, "hunt" is just a form of detection. I don't see the need to build a "hunt" team. IR teams detect intruders using two major modes: matching and hunting. Junior people spend more time matching. Senior people spend more time hunting. Both can and should do both functions. This inspired Rob Lee to blog a response, from which I extract his core argument: [Hunting] really isn’t, to me, about detecting threats... Hunting is a hypothesis-led approach to testing your environment for threats. The purpose, to me, is not in finding threats but in determining what gaps you have in your ability to detect and respond to them... In short, hunting, to me, is a way to assess your security (people, process, and technology) against threats while extending your automation footprint to better be prepared in the future. Or simply stated, it’s ...